Asana
Asana
New

Staff Detection Engineer

40k - 45k PLN/ mies.UoP
SeniorFull-time·Umowa o pracę
#448075·Dodano wczoraj·0
Źródło: justjoin.it
Aplikuj teraz

Tech Stack / Keywords

PythonSecuritySIEMCI/CD

Firma i stanowisko

Asana is a leading platform for human + AI collaboration with 13+ offices worldwide. The company focuses on security by proactively addressing threats and fostering a culture of security across its product and operations.

Wymagania

  • 8+ years in detection engineering, security operations, or threat hunting.
  • Strong Python skills, with experience in Git workflows, pull request code review, automated testing, and CI/CD.
  • Deep experience with detection-as-code, including test-driven detection logic, rule lifecycle management, and CI/CD pipelines.
  • Strong experience with SIEM platforms (e.g., Panther, Splunk, Elastic Security), including query languages, log schemas, and correlations.
  • Deep understanding of cloud and identity telemetry such as AWS, GCP audit logs, Okta system logs, and SaaS audit APIs.
  • Working knowledge of EDR tools (e.g., CrowdStrike, SentinelOne) and endpoint telemetry.
  • Fluency with attacker TTPs and MITRE ATT&CK, using them to drive coverage decisions.
  • Collaborative and pragmatic mindset with strong communication skills.
  • Demonstrated curiosity about AI tools and emerging technologies with willingness to learn and leverage them.

Obowiązki

  • Design, build, and maintain high-fidelity detections across cloud infrastructure (AWS, GCP), identity providers (e.g., Okta), SaaS environments, endpoints, and the software supply chain.
  • Own the detection-as-code pipeline in Panther, including rule structure, testing, code review, and CI/CD deployment.
  • Map and close coverage gaps against MITRE ATT&CK and relevant threat models.
  • Onboard and normalize new telemetry sources, ensuring logs are complete and queryable.
  • Measure and improve alert quality by tracking precision, time-to-triage, and false-positive rates.
  • Validate detections against real attacker behavior using purple-team exercises, atomic tests, and emulation.
  • Turn incidents and threat intelligence into durable detections in collaboration with incident responders.
  • Build enrichment and automation in the SOAR platform to provide context for alerts.

Nice to have:

  • Experience detecting software supply chain and CI/CD threats, including anomalies in build systems and developer ecosystems (e.g., npm, PyPI, GitHub Actions).
  • Experience with adversary emulation frameworks (e.g., Atomic Red Team, Caldera) or running purple-team exercises.
  • Experience with data engineering for security, such as log pipelines, schema design, or cost optimization for high-volume telemetry.

Benefity

  • Generous, transparent, and fair compensation system (base salary and RSUs).
  • Contract of Employment (UoP) with option of 50% tax deductible costs for author's rights usage.
  • Health insurance with dental and travel coverage (Lux Med).
  • Breakfast and lunch catering on office days.
  • Vacation allowance.
  • Career growth budget.
  • Home office setup budget.
  • Gym/Fitness card.
  • Fertility healthcare and family-forming support with Carrot.
  • Mental Health Support in Modern Health.
  • Group life insurance.
  • Provided MacBooks with accessories.
Płatne święta
Opieka zdrowotna
Firmowa stołówka
Karta sportowa
Premie
Udziały pracownicze

Inne informacje

Please be informed that the data controller is Asana, located in San Francisco, California. Personal data will be processed for recruitment purposes with rights for access, rectification, erasure, restriction, objection, portability, and complaints to supervisory authority. Provision of mandatory data is required by law; refusal may impede recruitment. Consent for additional data is voluntary and can be withdrawn. Data recipients include Just Join IT and other entities involved in recruitment processing.

Asana

Asana

23 aktywne oferty

Zobacz wszystkie oferty
Aplikuj teraz